CVE-2024-10220
1 分钟 阅读时间
该漏洞与 gitRepo 卷输入参数校验有关。上游收紧了目录参数校验逻辑,KLTS 对维护分支完成了对应回补。
漏洞影响
上游元数据给出的受影响范围:<= k8s1.28.11。
漏洞评分
该漏洞为高危漏洞,CVSS 评分为 8.1。
官方修复的版本
KLTS 修复的版本
- v1.27.16-lts.1 kubernetes/kubernetes#124531
- v1.26.15-lts.1 kubernetes/kubernetes#124531
- v1.25.16-lts.1 kubernetes/kubernetes#124531
- v1.24.17-lts.1 kubernetes/kubernetes#124531
- v1.23.17-lts.1 kubernetes/kubernetes#124531
- v1.22.17-lts.1 kubernetes/kubernetes#124531
- v1.21.14-lts.2 kubernetes/kubernetes#124531
- v1.20.15-lts.3 kubernetes/kubernetes#124531
- v1.19.16-lts.4 kubernetes/kubernetes#124531
- v1.18.20-lts.3 CVE-2024-10220.1.18.patch
- v1.17.17-lts.3 CVE-2024-10220.1.18.patch
- v1.16.15-lts.3 CVE-2024-10220.1.18.patch
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.
最后修改
2026.04.15
: docs: sync recent kubernetes-lts releases and CVEs (5ee2b8f3)